Hacking past authentication

Discussion in 'privacy general' started by Addelam, Nov 2, 2023.

  1. Addelam

    Addelam Registered Member

    Joined:
    May 9, 2021
    Posts:
    30
    Location:
    UK
    I think my Facebook account has been hacked despite a very strong password and an Authentication app.

    My research suggests hackers can bypass this if they know your mobile number, but my mobile number is not on the account...how is this possible?

    I have changed my password and ordered a physical key as I understand that is more secure.

    Any other suggestions?
     
  2. pegas

    pegas Registered Member

    Joined:
    May 22, 2008
    Posts:
    2,972
    Don't have your FB account linked to third party apps/services? If so, it's possible that someone hacked into one of them and got your FB login credentials.
     
  3. Addelam

    Addelam Registered Member

    Joined:
    May 9, 2021
    Posts:
    30
    Location:
    UK
    No, not that I am aware of.

    I checked the login record and it seems only I have logged in lately, Very strange. No sign of a rogue log in.
     
  4. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,597
    Location:
    Flat Earth Matrix
    They have probably stolen your session. Log out of all sessions, remove all devices, then re-login. I would also reset all browsers or at least clean caches/cookies.
    Code:
    https://www.facebook.com/device_based_login/?from_accounts_center=1
     
  5. Addelam

    Addelam Registered Member

    Joined:
    May 9, 2021
    Posts:
    30
    Location:
    UK
    Will do, thanks. How can they steal a session? have they maybe accessed m,y mobile SIM somehow??
     
  6. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,222
    Location:
    Member state of European Union
    If malware is present on the desktop/laptop system then it can just read cookies with session data.
    Malware may be in form of traditional Windows process, rogue system driver or browser extension. I would start by removing all unnecesarry browser extensions
     
  7. Addelam

    Addelam Registered Member

    Joined:
    May 9, 2021
    Posts:
    30
    Location:
    UK
    n.b. I checked and there was a mobile number added to my account. I could swear there was none there when I checked and indeed I was getting prompts to add one (which I did).

    Could they steal my session without using my mobile to log in?

    I noticed my Contact details had been accessed about a week ago, but I do not recall logging in that recently.
     
  8. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,222
    Location:
    Member state of European Union
    Yes, they can. If OS or browser is infected, then is game over,
    everything pwned. See my post above
     
    Last edited: Nov 2, 2023
  9. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,147
    Location:
    USA
    Not too difficult unfortunately A former coworker used to steal sessions from other users and get into their Yahoo email accounts, just to show that he could.
     
  10. Addelam

    Addelam Registered Member

    Joined:
    May 9, 2021
    Posts:
    30
    Location:
    UK
    How could he do this? And how to guard against it?

    n.b. I have meanwhile cleared all browsing data and am running a malware scan.

    But I do feel the session has somehow been stolen.
     
  11. Addelam

    Addelam Registered Member

    Joined:
    May 9, 2021
    Posts:
    30
    Location:
    UK
    Have done. Thanks.
     
  12. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,147
    Location:
    USA
    Log out when you're done and don't save the password in the browser. Not foolproof but helps.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.